Avamar: Behandle sikkerhetsinnstillinger for økt fra CLI

Summary: Denne artikkelen viser hvordan du administrerer sikkerhetsinnstillingene for Avamar-økten fra kommandolinjeverktøyet.

This article applies to This article does not apply to This article is not tied to any specific product. Not all product versions are identified in this article.

Instructions

MERK: Hvis du vil endre sikkerhetsinnstillingene for økten, må MCS startes på nytt.


Forhåndskontroller

Det anbefales å utføre følgende før du endrer sikkerhetsinnstillingene for økten.

  • Stopp alle sikkerhetskopieringer, replikering, og kontroller at ingen vedlikehold kjører (checkpoint/hfscheck/søppelrydding).
  • Kontroller at det finnes et gyldig sjekkpunkt på Avamar.



Oversikt over

Følgende skript som er installert på hver Avamar-server, brukes til å administrere sikkerhetsinnstillingene for økten.
Kjør skriptet som rotbruker.

enable_secure_config.sh


Vis gjeldende innstillinger:

enable_secure_config.sh --showconfig

Current Session Security Settings
----------------------------------
"encrypt_server_authenticate"                           ="false"
"secure_agent_feature_on"                               ="false"
"session_ticket_feature_on"                             ="false"
"secure_agents_mode"                                    ="unsecure_only"
"secure_st_mode"                                        ="unsecure_only"
"secure_dd_feature_on"                                  ="false"
"verifypeer"                                            ="no"

Client and Server Communication set to Default (Workflow Re-Run) mode with No Authentication.
Client Agent and Management Server Communication set to unsecure_only mode.
Secure Data Domain Feature is Disabled.


I eksemplet ovenfor er øktsikkerhet deaktivert.

Det finnes fire mulige støttede konfigurasjoner:

  1. Deaktivert
  2. Blandet singel
  3. Godkjent – enkel
  4. Godkjent-dobbel

Deaktivert

Følgende utdata viser innstillingene for deaktivert modus.

Kommandoen:
enable_secure_config.sh --showconfig

Utgang:
Current Session Security Settings
----------------------------------
"encrypt_server_authenticate"                           ="false"
"secure_agent_feature_on"                               ="false"
"session_ticket_feature_on"                             ="false"
"secure_agents_mode"                                    ="unsecure_only"
"secure_st_mode"                                        ="unsecure_only"
"secure_dd_feature_on"                                  ="false"
"verifypeer"                                            ="no"

Client and Server Communication set to Default (Workflow Re-Run) mode with No Authentication.
Client Agent and Management Server Communication set to unsecure_only mode.
Secure Data Domain Feature is Disabled.

Slik setter du sikkerhetsinnstillingene for økten til deaktivert:

Kommandoen:
enable_secure_config.sh --enable-all --undo

Utgang:
#########################  #########################
#########################  #########################
Disabling Avamar Security Features
Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml
Restart MCS for security features changes to take effect.
INFO: Administrator Server ping successful.
Setting Mutual server/client authentication
Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml

Done

Hvis innstillingene er endret, må MCS startes på nytt.


Blandet singel

Følgende utdata viser innstillingene for blandet enkeltmodus.

Kommandoen:
enable_secure_config.sh --showconfig

Utgang:
Current Session Security Settings
----------------------------------
"encrypt_server_authenticate"                           ="true"
"secure_agent_feature_on"                               ="true"
"session_ticket_feature_on"                             ="true"
"secure_agents_mode"                                    ="mixed"
"secure_st_mode"                                        ="mixed"
"secure_dd_feature_on"                                  ="true"
"verifypeer"                                            ="no"

Client and Server Communication set to Mixed mode with One-Way/Single Authentication.
Client Agent and Management Server Communication set to mixed mode.
Secure Data Domain Feature is Enabled.

Slik setter du sikkerhetsinnstillingene for økt til Mixed-Single:

Command:
enable_secure_config.sh --enable-all

Utgang:
#########################  #########################
#########################  #########################
Enabling Avamar Security Features

Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml
Restart MCS for security features changes to take effect.
INFO: Administrator Server ping successful.
Setting Mutual server/client authentication
Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml

Done

Kommando:
avmaint config --ava verifypeer=no

Utgang:
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<gsanconfig verifypeer="yes"/>

Hvis innstillingene er endret, må MCS startes på nytt.


Godkjent – enkel

Følgende utdata viser innstillingene for godkjent enkeltmodus.

Kommandoen:
enable_secure_config.sh --showconfig

Utgang:
Current Session Security Settings
----------------------------------
"encrypt_server_authenticate"                           ="true"
"secure_agent_feature_on"                               ="true"
"session_ticket_feature_on"                             ="true"
"secure_agents_mode"                                    ="secure_only"
"secure_st_mode"                                        ="secure_only"
"secure_dd_feature_on"                                  ="true"
"verifypeer"                                            ="no"

Client and Server Communication set to Authenticated mode with One-Way/Single Authentication.
Client Agent and Management Server Communication set to secure_only mode.
Secure Data Domain Feature is Enabled.

Slik setter du sikkerhetsinnstillingene for økt til Authenticated-Single:

Command:
enable_secure_config.sh --enable-secure-all

Utgang:
#########################  #########################
#########################  #########################
Enabling Avamar Security Features

Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml
Restart MCS for security features changes to take effect.
INFO: Administrator Server ping successful.
Setting Mutual server/client authentication
Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml

Done

Kommando:
avmaint config --ava verifypeer=no

Utgang:
<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<gsanconfig verifypeer="yes"/>

Hvis innstillingene er endret, må MCS startes på nytt.


Godkjent-dobbel

Følgende utdata viser innstillingene for godkjent dobbelmodus.

Kommandoen:
enable_secure_config.sh --showconfig

Utgang:
Current Session Security Settings
----------------------------------
"encrypt_server_authenticate"                           ="true"
"secure_agent_feature_on"                               ="true"
"session_ticket_feature_on"                             ="true"
"secure_agents_mode"                                    ="secure_only"
"secure_st_mode"                                        ="secure_only"
"secure_dd_feature_on"                                  ="true"
"verifypeer"                                            ="yes"

Client and Server Communication set to Authenticated mode with Two-Way/Dual Authentication.
Client Agent and Management Server Communication set to secure_only mode.
Secure Data Domain Feature is Enabled.

Slik setter du sikkerhetsinnstillingene for økten til Authenticated-Dual:

Command:
enable_secure_config.sh --enable-secure-all

Utgang:
#########################  #########################
#########################  #########################
Enabling Avamar Security Features

Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml
Restart MCS for security features changes to take effect.
INFO: Administrator Server ping successful.
Setting Mutual server/client authentication
Editing /usr/local/avamar/var/mc/server_data/prefs/mcserver.xml

Done

Hvis innstillingene er endret, må MCS startes på nytt.


Merk

Bruk følgende kommandoer for å starte MCS og sikkerhetskopieringsplanleggeren på nytt som administratorbruker:
mcserver.sh --restart --force
dpnctl start sched

Affected Products

Avamar
Article Properties
Article Number: 000222234
Article Type: How To
Last Modified: 12 Dec 2025
Version:  8
Find answers to your questions from other Dell users
Support Services
Check if your device is covered by Support Services.